Description
IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
Published: 2026-08-05
Score: 3.8 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Business Automation Workflow containers and traditional software are affected by an improper validation of server certificates, where the hostname is not verified against the presented certificate. The flaw corresponds to authentication weakness CWE‑297 and could allow connections to be established with an attacker‑controlled server that advertises a forged certificate, thereby exposing transmitted data to interception or tampering.

Affected Systems

All IBM Business Automation Workflow containers and traditional releases from 24.0.0 through 26.0.0, including interim fixes 005, 007, and 009, are affected. The product is IBM Business Automation Workflow containers and traditional.

Risk and Exploitability

The CVSS score of 3.8 indicates low severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker controlling the endpoint and presenting a fraudulent certificate during a TLS handshake. If successful, the attacker could intercept or alter communications, compromising confidentiality and integrity of the data exchanged with the workflow system.

Generated by OpenCVE AI on August 5, 2026 at 17:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading. Affected Product(s)Version(s)Remediation / FixIBM Business Automation Workflow containersV26.0.0Apply container 26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-26000-interim-fixes IBM Business Automation Workflow traditionalV26.0.0Apply traditional 26.0.0-IF001 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-26000-interim-fixes IBM Business Automation Workflow containersV25.0.0 - V25.0.0-IF005Apply container 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-containers-25000-interim-fixes IBM Business Automation Workflow traditionalV25.0.0 - V25.0.0-IF005Apply traditional 25.0.0-IF006 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-25000-interim-fixes IBM Business Automation Workflow containersV24.0.1 - V24.0.1-IF007Apply container 24.0.1-IF008 https://www.ibm.com/support/pages/node/7183042 IBM Business Automation Workflow traditionalV24.0.1 - V24.0.1-IF007Apply traditional 24.0.1-IF008 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24010-interim-fixes IBM Business Automation Workflow containersV24.0.0 - V24.0.0-IF009Apply container 24.0.0-IF010 https://www.ibm.com/support/pages/node/7159792 IBM Business Automation Workflow traditionalV24.0.0 - V24.0.0-IF009Apply traditional 24.0.0-IF010 https://www.ibm.com/support/pages/readme-ibm-business-automation-workflow-24000-interim-fixes


OpenCVE Recommended Actions

  • Upgrade IBM Business Automation Workflow containers to version 26.0.0‑IF001 or later, or apply the corresponding interim fix for the version in use.
  • Upgrade IBM Business Automation Workflow traditional to version 26.0.0‑IF001 or later, or apply the corresponding interim fix for the version in use.
  • Ensure that all client connections to the workflow system enforce strict hostname validation and do not disable SSL/TLS checks.

Generated by OpenCVE AI on August 5, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Business Automation Workflow fails to properly verify that the hostname matches the server certificate potentially allowing connections to an attacker-controlled server.
Title Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow containers July 2026
First Time appeared Ibm
Ibm business Automation Workflow Containers And Traditional
Weaknesses CWE-297
CPEs cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.0:interim_fix_009:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:24.0.1:interim_fix_007:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:25.0.0:interim_fix_005:*:*:*:*:*:*
cpe:2.3:a:ibm:business_automation_workflow_containers_and_traditional:26.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm business Automation Workflow Containers And Traditional
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Business Automation Workflow Containers And Traditional
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-05T17:25:51.335Z

Reserved: 2026-06-19T15:59:20.718Z

Link: CVE-2026-12730

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:30:07Z

Weaknesses
  • CWE-297

    Improper Validation of Certificate with Host Mismatch